Description
WordPress Plugin WooCommerce is prone to a security bypass vulnerability. Exploiting this issue may allow attackers to perform otherwise restricted actions and subsequently mark an order as paid without actually making a payment. WordPress Plugin WooCommerce version 6.3.0 is vulnerable; prior versions may also be affected.
Remediation
Update to plugin versions 3.5.10, 3.6.7, 3.7.3, 3.8.3, 3.9.5, 4.0.4, 4.1.4, 4.2.5, 4.3.6, 4.4.4, 4.5.5, 4.6.5, 4.7.4, 4.8.3, 4.9.5, 5.0.3, 5.1.3, 5.2.5, 5.3.3, 5.4.4, 5.5.4, 5.6.2, 5.7.2, 5.8.1, 5.9.1, 6.0.1, 6.1.2, 6.2.2, 6.3.1 or latest
References
Related Vulnerabilities
Jenkins Session Fixation Vulnerability (CVE-2018-1000409)
WordPress Plugin Zingiri Web Shop 'wpabspath' Parameter Remote File Include (2.2.0)
Joomla! Core Security Bypass (2.5.0 - 3.9.27)
WordPress Plugin YITH WooCommerce Gift Cards Unspecified Vulnerability (2.14.0)
Apache Traffic Server Improper Input Validation Vulnerability (CVE-2018-1318)